Authentication
How to send your API key, which header names work, and how the webhook secret is separate and can be rotated.
Every request to the API needs your API key. Create and manage keys on Integrations; only the business owner or an admin can open that page.
Sending your key
Send it in the X-API-Key header:
X-API-Key: YOUR_API_KEYAuthorization: Bearer YOUR_API_KEY (or the bare key with no Bearer) also works, for integrations that already use it.
On /api/v1, the key is accepted only in a header. The older /api/public/v1 path also accepts ?api_key= in the query string or an api_key field in the JSON body, for integrations built before /api/v1 existed. Put the key in a header on /api/v1 instead: a key in a URL or a request body can end up in access logs.
Key format
New keys start with upn_live_ followed by 48 hex characters. Keys created before that change start with lk_live_ and keep working; UPINOW looks a key up by a stored hash, never by its prefix.
A key is shown in full only once, right after you create or replace it. If you lose it, replace the key instead of trying to recover it.
Revoking and replacing
Revoke a key from Integrations and it stops working at once; nothing that sends it will authenticate again. Replace a key to get a new one with the same name while the old one is revoked in the same step, so you are never left without a working key mid-rotation.
Authentication errors
| Status | Code | When |
|---|---|---|
| 401 | missing_api_key |
No key was sent in a header (or, on /api/public/v1, the query string or body). |
| 401 | invalid_api_key |
The key is not recognised, or it has already been revoked. |
Webhook secret
The webhook secret is separate from your API key. It signs every webhook UPINOW sends you; it is never sent with your own requests. Find it, and rotate it, on Integrations.
Rotating the secret takes effect right away: the old secret stops working right away, and any webhook still retrying is signed with the new one. Rotate, then update your server right away. Any webhook your server rejects in between is retried, signed with the new secret.
Keep your API key and webhook secret on your server only. Never put either one in browser code or a mobile app bundle.